CISA has added two actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog and set a June 28 deadline for federal agencies to patch them. The first, CVE-2026-20230, is a critical SSRF flaw in Cisco Unified Communications Manager that can be exploited remotely without authentication via crafted HTTP requests; active exploitation was observed writing arbitrary files to affected endpoints. The second, CVE-2026-12569, is a critical RCE vulnerability in PTC Windchill and FlexPLM PLM products caused by deserialization of untrusted data, affecting all versions up to 11.0 and multiple branches through 13.0. Agencies must patch or stop using the affected products by the deadline under Binding Operational Directive 26-04.

2m read timeFrom bleepingcomputer.com
Post cover image
Table of contents
Critical flaw in PLM productsRelated Articles:
329 Impressions